Github Ops

作者 affaan-mef648e01899b无许可证275K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库3天前更新

GitHub操作、自動化、APIインテグレーション、およびCI/CDワークフロー。

仅含说明DevOps & Cloud
AI 生成的概览

通过 gh CLI 指导 GitHub 仓库操作:议题分类、PR 管理、CI/CD 调试、发布与安全监控。

功能
该技能提供通过 gh CLI 管理 GitHub 仓库的说明,涵盖议题分类(打标签、查重)、拉取请求审查与过期策略、CI/CD 失败排查、发布与变更日志准备,以及 Dependabot 和密钥扫描警报的检查。它给出具体的 gh 命令,用于列出、打标签、评论、查看日志和创建发布,并附带质量门禁清单。其产出是分类决策、审查状态评估、变更日志和发布命令,而非文件。
适用场景
适用于对 GitHub 仓库的议题进行分类、审查或合并拉取请求、排查失败的 CI 工作流、准备发布与变更日志,或监控 Dependabot 与安全警报。也适合开源维护者处理贡献者体验和过期议题等工作。
运行要求
需要 gh CLI,并通过 gh auth login 配置已认证的 GitHub 访问权限,同时需要访问 GitHub API 的网络连接。该技能不附带脚本,仅为说明文档。

GitHub Operations

Manage GitHub repositories with a focus on community health, CI reliability, and contributor experience.

When to Activate

  • Triaging issues (classifying, labeling, responding, deduplicating)
  • Managing PRs (review status, CI checks, stale PRs, merge readiness)
  • Debugging CI/CD failures
  • Preparing releases and changelogs
  • Monitoring Dependabot and security alerts
  • Managing contributor experience on open-source projects
  • User says "check GitHub", "triage issues", "review PRs", "merge", "release", "CI is broken"

Tool Requirements

  • gh CLI for all GitHub API operations
  • Repository access configured via gh auth login

Issue Triage

Classify each issue by type and priority:

Types: bug, feature-request, question, documentation, enhancement, duplicate, invalid, good-first-issue

Priority: critical (breaking/security), high (significant impact), medium (nice to have), low (cosmetic)

Triage Workflow

  1. Read the issue title, body, and comments
  2. Check if it duplicates an existing issue (search by keywords)
  3. Apply appropriate labels via gh issue edit --add-label
  4. For questions: draft and post a helpful response
  5. For bugs needing more info: ask for reproduction steps
  6. For good first issues: add good-first-issue label
  7. For duplicates: comment with link to original, add duplicate label
bash
# Search for potential duplicatesgh issue list --search "keyword" --state all --limit 20
# Add labelsgh issue edit <number> --add-label "bug,high-priority"
# Comment on issuegh issue comment <number> --body "Thanks for reporting. Could you share reproduction steps?"

PR Management

Review Checklist

  1. Check CI status: gh pr checks <number>
  2. Check if mergeable: gh pr view <number> --json mergeable
  3. Check age and last activity
  4. Flag PRs >5 days with no review
  5. For community PRs: ensure they have tests and follow conventions

Stale Policy

  • Issues with no activity in 14+ days: add stale label, comment asking for update
  • PRs with no activity in 7+ days: comment asking if still active
  • Auto-close stale issues after 30 days with no response (add closed-stale label)
bash
# Find stale issues (no activity in 14+ days)gh issue list --label "stale" --state open
# Find PRs with no recent activitygh pr list --json number,title,updatedAt --jq '.[] | select(.updatedAt < "2026-03-01")'

CI/CD Operations

When CI fails:

  1. Check the workflow run: gh run view <run-id> --log-failed
  2. Identify the failing step
  3. Check if it is a flaky test vs real failure
  4. For real failures: identify the root cause and suggest a fix
  5. For flaky tests: note the pattern for future investigation
bash
# List recent failed runsgh run list --status failure --limit 10
# View failed run logsgh run view <run-id> --log-failed
# Re-run a failed workflowgh run rerun <run-id> --failed

Release Management

When preparing a release:

  1. Check all CI is green on main
  2. Review unreleased changes: gh pr list --state merged --base main
  3. Generate changelog from PR titles
  4. Create release: gh release create
bash
# List merged PRs since last releasegh pr list --state merged --base main --search "merged:>2026-03-01"
# Create a releasegh release create v1.2.0 --title "v1.2.0" --generate-notes
# Create a pre-releasegh release create v1.3.0-rc1 --prerelease --title "v1.3.0 Release Candidate 1"

Security Monitoring

bash
# Check Dependabot alertsgh api repos/{owner}/{repo}/dependabot/alerts --jq '.[].security_advisory.summary'
# Check secret scanning alertsgh api repos/{owner}/{repo}/secret-scanning/alerts --jq '.[].state'
# Review dependency bumps — merging is a user-authorized action (propose, never auto-merge)gh pr list --label "dependencies" --json number,title
  • Review safe dependency bumps and propose merges for user approval — never auto-merge
  • Flag any critical/high severity alerts immediately
  • Check for new Dependabot alerts weekly at minimum

Quality Gate

Before completing any GitHub operations task:

  • all issues triaged have appropriate labels
  • no PRs older than 7 days without a review or comment
  • CI failures have been investigated (not just re-run)
  • releases include accurate changelogs
  • security alerts are acknowledged and tracked

来源与署名

来源:affaan-m/ecc位于docs/ja-JP/skills/github-ops提交ef648e0

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架